Impact
An unauthenticated local file inclusion flaw exists in Version 2.4.11 and earlier of the Restaurant Menu by MotoPress plugin. The vulnerability allows an attacker to include arbitrary files on the server that are normally inaccessible to web users, potentially exposing sensitive configuration files or other private data. No explicit mention of remote code execution is provided, but the availability of arbitrary file discovery can be a stepping stone to other attacks if the server environment is misconfigured.
Affected Systems
The issue affects installations of the WordPress plugin "Restaurant Menu by MotoPress" by jetmonsters, specifically all versions up to and including 2.4.11. Users running any of these iterations are susceptible to the exploitation described.
Risk and Exploitability
The flaw carries a CVSS score of 8.1, indicating high impact. The EPSS score is not available, so the current exploitation probability is unknown, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is likely through a crafted request to the plugin’s URL, and because no authentication is required, the vulnerability is exploitable by any user who can reach the affected WordPress installation.
OpenCVE Enrichment